OAuth Authentication

Exchange OAuth authorization code

Changed on

Atomically consumes a short-lived callback code and returns the user's session. The request must use the same project anon key and exact redirect_url that initiated the flow.

post/auth/oauth/exchange

Request

  • Base URL: https://api.volcano.dev
  • URL: https://api.volcano.dev/auth/oauth/exchange
  • Auth: HTTP bearer

Request body

codestring required
redirect_urlstring uri required

Response

Authorization code consumed and session created

access_tokenstring required

JWT access token (expires after configured lifetime)

token_typestring required
expires_ininteger required

Access token lifetime in seconds

refresh_tokenstring

Long-lived token for getting new access tokens. Omitted when the request uses eligible HttpOnly cookie session storage.

Example response

{
  "token_type": "bearer"
}

Changes

    • ▲

      the response's body type changed from no type to object for status

    • ○

      added the optional property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      endpoint added